Skip to content

Upgrade to Go 1.27.2 - #73

Open
tnsardesai wants to merge 1 commit into
mainfrom
hypeship/go-1.27
Open

tnsardesai wants to merge 1 commit into
mainfrom
hypeship/go-1.27

Conversation

@tnsardesai

@tnsardesai tnsardesai commented Oct 9, 2026 •

Copy link
Copy Markdown

Summary

Go 1.25 and older are out of support now that Go 1.27 has shipped. This moves the repo to the latest patch release, Go 1.27.2.

module before after
go.mod go 1.25.0 go 1.27.2

Other places that pin the Go toolchain:

  • CI and release workflows read go-version-file: go.mod

Other changes needed for the upgrade:

  • go mod tidy dropped 106 stale go.sum lines for module versions no longer in the graph.

Breaking changes and GODEBUG review

Raising the go line changes these defaults (none are overridden in this repo, via godebug blocks, //go:debug or GODEBUG env):

  • Go 1.26: urlstrictcolons=1 (url.Parse rejects extra colons in the host), cryptocustomrand=0 (crypto ignores caller-supplied rand readers), tlssecpmlkem=1 (SecP256r1MLKEM768/SecP384r1MLKEM1024 on by default)
  • Go 1.27: tracebacklabels=1 (pprof goroutine labels are printed in tracebacks)

Removed outright in 1.27 (new behavior regardless of the go line): asynctimerchan, gotypesalias, tls10server, tlsrsakex, tls3des, tlsunsafeekm, x509keypairleaf. None are set here.

Toolchain changes that apply as soon as 1.27 builds the code: encoding/json runs on the v2 implementation (same behavior, different error text), HTTP/1 Response.Body.Close drains unread bodies, ServeMux trailing-slash redirects are 307 (1.26), Green Tea GC is on (1.26), go test runs the stdversion vet check, and gofmt alignment changed slightly.

Repo-specific findings:

  • url.Parse(baseURL) only sees the configured API base URL; malformed hosts with stray colons are now rejected instead of silently accepted.

Verification

  • hypeman-cli: go build ./... pass, go vet ./... pass, go test -short ./... 3 ok / 0 failed on 1.27.2 (baseline on the pre-upgrade toolchain: 3 ok / 0 failed)

Note

Medium Risk
Raising the Go version enables new runtime/stdlib defaults across networking, TLS, and URL parsing without code changes; tests passed but production edge cases around url.Parse(baseURL) could surface.

Overview
Bumps the module go directive from 1.25.0 to 1.27.2 so builds and CI (workflows that use go-version-file: go.mod) run on a supported toolchain.

go mod tidy shrinks go.sum by dropping checksums for modules no longer in the dependency graph; direct require entries in go.mod are otherwise unchanged in this diff.

No Go source edits—behavior shifts come from 1.26/1.27 language and runtime defaults (e.g. stricter url.Parse host handling for configured API base URLs in pkg/cmd, TLS/crypto defaults, encoding/json implementation). The PR description documents GODEBUG and verification (build, vet, test -short).

Reviewed by Cursor Bugbot for commit 576b79f. Bugbot is set up for automated code reviews on this repo. Configure here.

@tnsardesai
tnsardesai marked this pull request as ready for review October 9, 2026 19:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants